Ivanti Sentry Root RCE Added to KEV
CISA flags an Ivanti Sentry root RCE as actively exploited while Microsoft ships a record 206 Patch Tuesday fixes.

CISA adds Ivanti Sentry CVE-2026-10520 to KEV after attackers weaponize a pre-auth root RCE within 24 hours of disclosure. The OS command injection vulnerability in Ivanti Sentry (CVSS 10.0) allows any unauthenticated remote attacker to execute arbitrary commands as root on affected versions prior to R10.5.2, R10.6.2, and R10.7.1. As BleepingComputer reported, CISA has ordered federal agencies to patch by Sunday, and SecurityWeek noted that honeypots are already seeing exploitation attempts. watchTowr Labs published a detailed technical analysis, and Dark Reading highlighted that active exploitation began within 24 hours of the public PoC release. Organizations running Ivanti Sentry should treat this as an emergency patching priority.
Microsoft's June 2026 Patch Tuesday fixes a record 206 vulnerabilities, including three actively exploited zero-days and a critical Windows DHCP Client RCE (CVE-2026-44815). The DHCP Client stack-based buffer overflow (CVSS 9.8) allows an unauthenticated attacker to execute code over the network, making it one of the highest-severity items in the batch. As The Hacker News summarized, the update addresses three zero-days already under active exploitation. CrowdStrike's analysis and Cisco Talos's write-up both emphasize the breadth of this release, which BleepingComputer covered as the largest Patch Tuesday in Microsoft's history.
Three critical Ubiquiti UniFi OS and UID Enterprise Agent flaws (CVE-2026-47370, CVE-2026-47369, CVE-2026-47367) enable command injection and privilege escalation from a low-privileged network position. CVE-2026-47370 and CVE-2026-47369 both affect UniFi OS devices, with the former allowing command injection and the latter enabling privilege escalation — each rated CVSS 9.9. CVE-2026-47367 targets the UID Enterprise Agent on the host device with a separate command injection vector. An attacker who already has low-privileged network access can chain these to gain full control of affected Ubiquiti hardware. No public PoC or KEV listing has been reported yet, but the preconditions (network access, low privileges) are common in compromised enterprise environments.
Fortinet FortiSandbox ships patches for a critical OS command injection vulnerability (CVE-2026-25089, CVSS 9.8) affecting multiple versions including 5.0.0–5.0.5, 4.4.0–4.4.8, and all 4.2.x releases. As The Hacker News reported, the flaw allows an unauthenticated attacker to execute arbitrary OS commands on the FortiSandbox appliance. Cyber Security News noted that exploitation could lead to full compromise of the sandbox environment, potentially exposing malware analysis data and allowing attackers to pivot deeper into the network. Fortinet has released updates; administrators should prioritize patching given the unauthenticated, pre-auth nature of the attack vector.
Adobe Campaign Classic (CVE-2026-48303, CVSS 10.0) and a wave of critical flaws across WordPress plugins, ClipBucket, and MariaDB demand attention from platform-specific teams. The Adobe Campaign Classic incorrect authorization bug (versions 7.4.3 build 9394 and earlier) can lead to arbitrary code execution in the current user's context, as Vypr Intelligence detailed. Separately, the MariaDB server (CVE-2026-49261, CVSS 10.0) allows shell command execution when wsrep_notify_cmd is enabled across multiple version branches. WordPress-adjacent products are also under fire: the Amasty Order Attributes plugin for Magento 2 (CVE-2026-53787) enables unauthenticated arbitrary file upload, and the Hippoo Mobile App for WooCommerce (CVE-2026-49060) suffers from privilege escalation. ClipBucket v5 (CVE-2026-45060, CVE-2026-42846) has both a pre-auth blind SQL injection and an authenticated command injection via its Remote Play feature.
Hardcoded credentials and authentication bypasses plague IoT, mobile, and enterprise applications — including Yarbo smart devices, IEI Remote Management, and a Turkish restaurant POS app. The Yarbo Android/iOS app (CVE-2026-10557, CVSS 9.8) embeds identical MQTT broker credentials in the binary, extractable via APK decompilation, as CISA's ICS advisory warned. IEI Integration Corp's iRM-IEI Remote Management (CVE-2026-11849, CVSS 9.8) ships with hardcoded database credentials granting full admin access. The Pause+ Mobile App (CVE-2026-6853, CVSS 9.8) from Başbelen Group lacks rate limiting on authentication attempts, enabling brute-force bypass. The phpBB OAuth implementation (CVE-2026-48611, CVSS 9.8) allows account hijacking even when OAuth is not configured, affecting default installations. These flaws share a common pattern: basic security hygiene failures that attackers can trivially weaponize at scale.